Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Massive hack-for-hire scandal rocks Italian political elites
- JPMorgan begins suing customers who allegedly stole thousands of dollars in ‘infinite money glitch’
- Free, France’s second largest ISP, confirms data breach after leak
- Change Healthcare breach hits 100M Americans
- Brazen crims selling stolen credit cards on Meta’s Threads
- Inside a firewall vendor’s 5-year war with the Chinese hackers hijacking its devices
- Microsoft delays Windows Recall again, now by December
For the more technical
- We patched CVE-2024-38030, found another Windows Themes spoofing vulnerability
- An update on Windows Downdate
- A vulnerability in the Common Log File System (CLFS) driver allows a local user to gain elevated privileges on Windows 11
- QNAP fixes NAS backup software zero-day exploited at Pwn2Own
- Zero-day vulnerabilities in live streaming cameras with the help of AI
- RCE vulnerability in QBittorrent
- Rare case of privilege escalation patched in LiteSpeed Cache plugin
- ChatGPT-4o guardrail jailbreak: Hex encoding for writing CVE exploits
- New tool bypasses Google Chrome’s new cookie encryption system
- Katz and mouse game: MaaS infostealers adapt to patched Chrome defenses
- EmeraldWhale: 15k cloud credentials stolen in operation targeting exposed Git config
- The infostealers, RedLine and META, taken down by international coalition
- Mishing in motion: Uncovering the evolving functionality of FakeCall malware
- Jumpy Pisces engages in Play ransomware
- Massive PSAUX ransomware attack targets 22,000 CyberPanel instances
- Fog and Akira ransomware targets SonicWall VPNs to breach corporate networks
- Hybrid Russian espionage and influence campaign aims to compromise Ukrainian military recruits and deliver anti-mobilization narratives
- Inside the open directory of the “You Dun” threat group
- CloudScout: Evasive Panda scouting cloud services
- Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network
- New tradecraft of Iranian cyber group Aria Sepehr Ayandehsazan aka Emennet Pasargad (PDF)
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.